logo

China-Nexus Hackers Target Linux Devices to Redirect Traffic and Deploy Malware

ID: 8d8eb01c-23d4-5f9a-b419-8fd353084557

STIX ID: report--8d8eb01c-23d4-5f9a-b419-8fd353084557

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-02-06

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

**Executive Summary:** DKnife is an advanced adversary-in-the-middle (AitM) framework that compromises Linux-based routers and edge devices to perform deep packet inspection and hijack legitimate software updates—redirecting Android APK and Windows downloads to attacker-controlled binaries and deploying backdoors such as ShadowPad and DarkNimbus; it comprises seven ELF components (e.g., dknife.bin, yitiji.bin, postapi.bin) that create a virtual local network, exfiltrate credentials, and remain active as of January 2026, with evidence linking its infrastructure to WizardNet/Spellbinder and with a focus on Chinese services and users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.